You have 0 free articles left this month.
Big Law

Court Services Victoria confirms data breach at Bendigo Law Courts

Almost 30,000 lines of court data have potentially been compromised in a breach carried out by a prominent hacker, 2019.

July 30, 2026 By David Hollingworth
Share this article on:
expand image

Court Services Victoria has confirmed it is responding to a “data security incident” after a prolific hacker published a raft of case-related data to a popular underground hacking forum.

The hacker – 2019, who has claimed attacks on a string of Australian organisations in 2026 – claimed in a 15 July forum post to have accessed court systems, alongside a claim that the breach had impacted more than 28,600 lines of court records relating to cases heard at the consolidated court facility.

 
 

A sample of the data was published to the forum as evidence of the hack, with the rest of the data made available for free on an anonymous hosting service.

Court Services of Victoria is aware of the hacker’s claims and is investigating the full extent of the breach.

“Court Services Victoria (CSV) is aware of a data security incident impacting the Magistrates Court of Victoria and the Children’s Court of Victoria,” the chief executive of Court Services Victoria, Louise Anderson, told Cyber Daily.

“The incident led to unauthorised access to some information used to link court participants to online hearings.

“CSV immediately investigated and shut down the way the information was accessed, strengthened security and continues to monitor the system. All relevant authorities have been notified of the incident and are assisting with the investigation and response.”

Anderson said that information used to establish online hearings at the Magistrates Court of Victoria and the Children’s Court of Victoria between 2022 and 2026 was accessed. Impacted court locations include Bendigo, Castlemaine, Echuca, Kerang, Kyneton, Maryborough, Mildura, Ouyen, Robinvale, and Swan Hill.

“The system from which this data comes is separate from the case management system (CMS) used by the two courts and does not contain information about court proceedings from that system,” Anderson said.

While some of the data accessed was already on the public record – including case titles and numbers, hearing dates and times, courtrooms, and participant names – Anderson said data such as “email addresses and/or a description of the person’s role in the matter (i.e. lawyer, court staff, observer)” was also accessed.

“Our investigation and response remain ongoing, and we will continue to provide updates as further information becomes available,” Anderson said.

“In the meantime, if you were involved in a case in the Magistrates Court of Victoria and the Children’s Court of Victoria during the time frame and locations noted above and are concerned that you may be impacted, you can call 9087 6116 between 9am and 5pm, Monday to Friday.”

Anderson said that maintaining the security of court users was CSV’s “highest priority” and that further updates will be made to its Frequently Asked Questions web page.

Who is 2019?

2019 has been targeting Australian organisations since early 2026, with recent victims including the Melbourne International Film Festival, a healthcare clinic in Canberra, and the Australian Centre for the Moving Image.

The Australian Productivity Commission’s email systems were also breached by 2019, and the access gained was used to directly harass several Australian journalists.

Very little else is known about their identity, nor why they may be focusing their criminal activity on Australian entities.

This article first appeared on Cyber Daily, Lawyers Weekly’s sister brand.

Want to see more stories from trusted news sources?
Make Lawyers Weekly a preferred news source on Google.
Click here to add Lawyers Weekly as a preferred news source.